2021 - Page 173 of 759

Debian 11 — 9base — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — 9base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-1935 Upstream summary: 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Oracle Linux 8 — edk2 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — edk2 — vulnerability — patch and remediation guide (ELSA-2021-3066)

🟠 High   ⏱ 15–60 min  Last verified: 12 October 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2021-3066 Related CVEs: CVE-2021-38575 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
IBM AIX 7.1 — CVE-2021-29754 — privilege escalation — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2021-29754 — privilege escalation — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 12 October 2021 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2021-29754, IBM Support Bulletin CVE: CVE-2021-29754 NVD summary: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association […]

Read more
openSUSE Tumbleweed — python36-bleach — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-bleach — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2018-7753 CVE-2020-6817 CVE-2020-6816 CVE-2021-23980 Upstream summary: An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the […]

Read more
FreeBSD 13 — rubygem-doorkeeper — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-doorkeeper — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-doorkeeper — token revocation vulnerability Related CVEs: CVE-2018-1000211 Upstream summary: NVD reports: Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that […]

Read more
Oracle Linux 8 — The SJIS Character Encoding is Unsupported — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — The SJIS Character Encoding is Unsupported

🟠 High   ⏱ 5–30 min  Last verified: 11 October 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: Oracle Bug 36686119 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
FreeBSD 13 — php5-soap — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php5-soap — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 CVE-2015-6834 CVE-2015-6835 CVE-2015-6836 CVE-2015-6837 CVE-2015-6838 Upstream summary: PHP reports: Core: Fixed bug #70172 (Use After Free Vulnerability in unserialize()). Fixed bug […]

Read more
FreeBSD 13 — lxr — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lxr — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lxr — multiple XSS vulnerabilities Related CVEs: CVE-2009-4497 Upstream summary: Dan Rosenberg reports: There are several cross-site scripting vulnerabilities in LXR. These vulnerabilities could allow an attacker to execute scripts […]

Read more
CHAT